2025 CVE Vulnerabilities
45,296 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2073 | HIGH | 8.8 | 0.2% | Apr 16, 2025 | Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with... |
| CVE-2025-24911 | MEDIUM | 4.9 | 0.4% | Apr 16, 2025 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable... |
| CVE-2025-24910 | MEDIUM | 4.9 | 0.3% | Apr 16, 2025 | Overview XML documents optionally contain a Document Type Definition (DTD), which, among other features, enable... |
| CVE-2025-24909 | MEDIUM | 4.4 | 0.2% | Apr 16, 2025 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed... |
| CVE-2025-24908 | MEDIUM | 6.8 | 0.4% | Apr 16, 2025 | Overview The product uses external input to construct a pathname that should be within a restricted directory, ... |
| CVE-2025-24907 | MEDIUM | 6.8 | 0.4% | Apr 16, 2025 | Overview The product uses external input to construct a pathname that should be within a restricted directory, ... |
| CVE-2025-1704 | MEDIUM | 6.5 | 0.2% | Apr 16, 2025 | ComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users... |
| CVE-2025-1568 | HIGH | 8.8 | 0.4% | Apr 16, 2025 | Access Control Vulnerability in Gerrit chromiumos project configuration in Google ChromeOS 16063.87.0 allows an attacker... |
| CVE-2025-1566 | HIGH | 7.5 | 0.2% | Apr 16, 2025 | DNS Leak in Native System VPN in Google ChromeOS Dev Channel on ChromeOS 16002.23.0 allows network observers to expose p... |
| CVE-2025-0758 | MEDIUM | 6.1 | 0.1% | Apr 16, 2025 | Overview The product specifies permissions for a security-critical resource in a way that allows that resource to be... |
| CVE-2025-0757 | MEDIUM | 4.4 | 0.2% | Apr 16, 2025 | Overview The software does not neutralize or incorrectly neutralize user-controllable input before it is placed ... |
| CVE-2025-0756 | CRITICAL | 9.1 | 0.8% | Apr 16, 2025 | Overview The product receives input from an upstream component, but it does not restrict or incorrectly restric... |
| CVE-2025-43703 | MEDIUM | 5.4 | 0.2% | Apr 16, 2025 | An issue was discovered in Ankitects Anki through 25.02. A crafted shared deck can result in attacker-controlled access ... |
| CVE-2025-32791 | MEDIUM | 4.3 | 0.2% | Apr 16, 2025 | The Backstage Scaffolder plugin houses types and utilities for building scaffolder-related modules. A vulnerability in t... |
| CVE-2025-32789 | LOW | 3.7 | 0.3% | Apr 16, 2025 | EspoCRM is an Open Source Customer Relationship Management software. Prior to version 9.0.7, users can be sorted by thei... |
| CVE-2025-32787 | LOW | 3.1 | 0.3% | Apr 16, 2025 | SoftEtherVPN is a an open-source cross-platform multi-protocol VPN Program. Versions 5.02.5184 to 5.02.5187 are vulnerab... |
| CVE-2025-32783 | MEDIUM | 4.3 | 0.3% | Apr 16, 2025 | XWiki Platform is a generic wiki platform. A vulnerability in versions from 5.0 to 16.7.1 affects users with Message Str... |
| CVE-2025-32433 | CRITICAL | 10 | 97.7% | Apr 16, 2025 | Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and O... |
| CVE-2025-31478 | HIGH | 8.2 | 0.3% | Apr 16, 2025 | Zulip is an open-source team collaboration tool. Zulip supports a configuration where account creation is limited solely... |
| CVE-2025-25230 | HIGH | 7.8 | 0.1% | Apr 16, 2025 | Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Clie... |
| CVE-2025-3730 | MEDIUM | 5.5 | 0.3% | Apr 16, 2025 | A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.func... |
| CVE-2025-3729 | CRITICAL | 9.8 | 3.0% | Apr 16, 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen... |
| CVE-2025-3728 | HIGH | 7.8 | 0.3% | Apr 16, 2025 | A vulnerability classified as critical was found in SourceCodester Simple Hotel Booking System 1.0. This vulnerability a... |
| CVE-2025-3727 | CRITICAL | 9.8 | 0.6% | Apr 16, 2025 | A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. This affects an unknown part of the com... |
| CVE-2025-3620 | HIGH | 8.8 | 0.3% | Apr 16, 2025 | Use after free in USB in Google Chrome prior to 135.0.7049.95 allowed a remote attacker to potentially exploit heap corr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now